North Texas Commercial Cleaning Experts | Call (214)-586-0257
Print to PDF
Document IDHWB-QMS-7.2
Version3.0.0
Statusâ—Ź APPROVED
Clause7.2 (Competence) & 7.5 (PII Vault)
Document Control
Document Title Employee Onboarding & Sensitive PII Vault SOP
Document ID HWB-QMS-7.2
Version 3.0.0
Status APPROVED
Author George (Systems Architect, mbB, Lead ISO Auditor)
Approved By Humberto Dominguez, CEO
Date 09/21/2026
ISO Standards ISO 9001:2015 Clause 7.2 & ISO 27001:2022 / SOC 2 Type II

Standard Operating Procedure: Employee Onboarding & Sensitive PII Vault Protocol

1.0 Purpose

This procedure establishes the clinical standard for recruiting, screening, onboarding, and securing the personal data of all workforce personnel at HWB Cleaning Services LLC. It guarantees that technicians are verified, trained, badged, and equipped from day one, while protecting their sensitive identification and banking data under Texas Bus. & Com. Code § 521.053, ISO 27001, and SOC 2 Type II regulations.

2.0 Scope

Applies to all W-2 commercial cleaning technicians, 1099 subcontractor cleaning crews, field supervisors, and administrative personnel managed within the SigmaFidelity™ Operations Hub.

3.0 Public Workforce Intake Portal (/work-with-us)

Public recruitment is routed through the central recruitment portal (http://mop.test:5000/work-with-us):

  1. Two-Track Intake: Candidates select either Track 1 (W-2 Commercial Cleaning Technician) or Track 2 (1099 Subcontractor Partner Crew). The portal supports direct URL deep-linking (?track=subcontractor).
  2. Phone Number Masking (PROC-002): All applicant telephone numbers must be validated and automatically masked as (###)-###-#### on every keystroke. Arbitrary characters, incomplete 10-digit strings, and unformatted entries are blocked before submission.
  3. Zero Plaintext Collection at Intake: Public application forms strictly prohibit requesting Social Security Numbers, ITINs, or bank account numbers during initial intake. Sensitive PII is collected only after a formal conditional offer is extended.
  4. Poka-Yoke Error Handling: Native browser alert() popups are eradicated. All input failures produce styled, accessible error banners (#tech-error-box and #sub-error-box) with autofocus on the first invalid field.

4.0 Candidate Pool (ATS) & Onboarding Workflow

  1. Intake Ingestion: Completed applications populate the Candidate Pool (ATS) subtab in the Backoffice Operations Hub (/admin/operations?view=workforce&subtab=candidates).
  2. Vetting & Background Clearance: Before facility deployment, candidates undergo DPS criminal history checks, I-9 employment verification, and reference validation. DPS clearance dates and I-9 completion dates are logged in the employee profile.
  3. Promotion to Personnel Roster: Clicking the "+ Onboard" action button opens the hiring modal. Assigning an hourly pay rate, facility assignment (e.g., Collin College Frisco Campus, NTTA), and primary role automatically creates a unique employee number (HWB-EMP-####) in the "Employees" table and updates the applicant record to Hired.

5.0 Form W-4, Banking & The Sensitive PII Vault Protocol (SEC-001)

HWB enforces zero plaintext storage for all government identifiers and banking credentials:

Data Field Input & Display Standard Database Storage Standard Access & Reveal Protocol
Social Security Number (SSN) / ITIN Password-bulleted entry with live ###-##-#### keystroke formatting. Default display: ***-**-####. AES-256 Fernet column encryption (ssn_encrypted) with dedicated last-four search index (ssn_last_four). Restricted to Executive, Admin, and Operations roles. Clicking "Reveal" displays decrypted digits with an automated 30-second countdown timer. Auto-remasks immediately upon timeout or modal dismissal.
Direct Deposit Checking / Savings Account Default display masked as ••••••••####. AES-256 Fernet column encryption (direct_deposit_account_encrypted) and last-four index. Protected from general staff view. Raw account numbers are never transmitted across standard GET queries or payroll CSV exports.
Bank Routing Number (ABA) 9-digit validated routing format. Validated against Federal Reserve routing directory. Visible to authorized payroll managers for ACH NACHA direct deposit file generation.

6.0 Immutable Audit Telemetry & Access Controls

  1. Audit Logging: Every unmasking of an employee's Social Security Number is logged to the "GlobalActivities" table with accessor user ID, username, employee ID, timestamp, and client IP address.
  2. Unauthorized Access Quarantine: If an unauthorized user (such as Field Sales) attempts to access sensitive identification endpoints (POST /api/v1/hr/employees/<id>/reveal-ssn), the gateway rejects the request with HTTP 403 Forbidden and automatically generates a SECURITY_VIOLATION event in the security ledger.
  3. Automated Security Lockout Protocol: When an employee's status changes to Terminated or Fired, the system automatically sets their badge status to Revoked, records the termination date, and marks linked candidate records as terminated.

7.0 Verification (Zero-Defect Check)

  • Employee file contains signed Form W-4, verified I-9, and state ID expiration date.
  • Social Security Number displays exclusively as ***-**-#### upon loading the dossier.
  • Direct deposit account displays exclusively as ••••••••####.
  • Clicking "Reveal" records a verifiable entry in "GlobalActivities".
  • Exported payroll summaries contain zero plaintext Social Security or bank account numbers.

8.0 Revision History

Version Date Author Change Description
3.0.0 09/21/2026 George (Systems Architect) Integrated SEC-001 Sensitive PII Vault protocol (AES-256 column encryption for SSN/ITIN and bank accounts), 30-second audited timed reveal, automated security lockout protocol, and public intake phone masking (PROC-002). Approved by Humberto Dominguez, CEO.
2.0.0 05/21/2026 George Total modernization. Added 2026 mandates and Tier 6 telemetry.
1.0.0 02/28/2026 Gemini Initial Release.
Document Structure